Trojan

Trojan.Agent.CBDT removal tips

Malware Removal

The Trojan.Agent.CBDT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.CBDT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Attempts to disable browser security warnings
  • Harvests credentials from local FTP client softwares
  • Collects information to fingerprint the system

How to determine Trojan.Agent.CBDT?


File Info:

name: B3FA9C23125BE3C0CA2C.mlw
path: /opt/CAPEv2/storage/binaries/4fbd2cce20aa4a441cbe963e640025d34c0716c21077af06d6480eb40a46f9ee
crc32: CCAEDDE4
md5: b3fa9c23125be3c0ca2c274bbd1e08a7
sha1: 72484cea2c8692a152d95eb17d75b96302e0503d
sha256: 4fbd2cce20aa4a441cbe963e640025d34c0716c21077af06d6480eb40a46f9ee
sha512: 55d6eb4cc661d888c1894bd4f3c7dda7e714c77c1aabca91824f05c2e8ecdf5a883cd8d09e16d767d4b7a60e68e664745dac02dc67261142ef6998c9882a26c5
ssdeep: 6144:KCRXsFX5nRxeV0zQPm2nmASrleJ76XVw5Ofx:duXHYizcBNEMGXVJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1248402A6A14ACDFDEC04C9B25DEDDD4CD9792CA58BF8D2933B947E0AE4335A40E70058
sha3_384: 7f5067476c65c54d638f33ba6a57eab3eb385ac625f296716cff9c3e79584c56037f0b83618582c7772a62a4d7c0431b
ep_bytes: 68c4714500e8eeffffff000000000000
timestamp: 2016-11-19 21:13:51

Version Info:

Translation: 0x0409 0x04b0
Comments: Preorganise
CompanyName: EA Sports
ProductName: Stvlagets6
FileVersion: 4.04.0009
ProductVersion: 4.04.0009
InternalName: Fritstilles0
OriginalFilename: Fritstilles0.exe

Trojan.Agent.CBDT also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.CBDT
ALYacTrojan.Agent.CBDT
CylanceUnsafe
VIPRETrojan.Agent.CBDT
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 0055e3991 )
AlibabaTrojanSpy:Win32/Injector.66e6acba
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.3125be
VirITTrojan.Win32.VBPack_Heur
CyrenW32/Gosys.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DHUB
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packer.VbPack-0-6334882-0
KasperskyTrojan-Spy.Win32.Zbot.ywmu
BitDefenderTrojan.Agent.CBDT
NANO-AntivirusTrojan.Win32.DHUB.eipfll
ViRobotTrojan.Win32.Agent.380928.X
AvastWin32:VBCrypt-DEE [Trj]
TencentMalware.Win32.Gencirc.114aa1de
Ad-AwareTrojan.Agent.CBDT
SophosML/PE-A + Mal/FareitVB-M
ComodoMalware@#3i8q1wrknaoo5
DrWebTrojan.Siggen6.32796
TrendMicroTSPY_HPLOKI.SMVB1
McAfee-GW-EditionBehavesLike.Win32.Trojan.fm
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.b3fa9c23125be3c0
EmsisoftTrojan.Agent.CBDT (B)
GDataTrojan.Agent.CBDT
GoogleDetected
AviraTR/Dropper.VB.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.3C54
KingsoftWin32.Troj.GenericKD.v.(kcloud)
ArcabitTrojan.Agent.CBDT
MicrosoftPWS:Win32/Zbot!VM
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
Acronissuspicious
McAfeeFareit-FGY!B3FA9C23125B
TrendMicro-HouseCallTSPY_HPLOKI.SMVB1
RisingTrojan.Injector!1.B459 (CLASSIC)
YandexTrojan.Injector!4677yPphir8
IkarusTrojan.VB.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.EJWI!tr
BitDefenderThetaGen:NN.ZevbaF.34784.xm0@aGtBjFni
AVGWin32:VBCrypt-DEE [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Agent.CBDT?

Trojan.Agent.CBDT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment